issue-discover
Warn
Audited by Socket on Feb 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The Issue Discover skill is coherently aligned with its purpose of orchestrating issue creation and discovery via phased, CLI-driven workflows. Security concerns center on the mandatory local reads of sensitive config/role data and the autonomous auto mode, which could enable unintended actions if inputs are manipulated. Overall, the design appears benign with moderate risk; mitigate by tightening access controls around local config files, enforcing strict input validation, and requiring explicit user confirmation in auto mode for high-risk operations.
Confidence: 75%Severity: 75%
Audit Metadata